PT-2023-24775 · Twig+1 · Twig+1
Scgajge12
·
Published
2023-06-14
·
Updated
2023-06-22
·
CVE-2023-34251
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 1.7.42
Description
The issue allows for server-side template injection, which can lead to remote code execution. This can be achieved by embedding malicious PHP code on the administrator screen by a user with page editing privileges. The vulnerability exploits the
system function in the Twig template engine, allowing an attacker to execute arbitrary system commands.Recommendations
For Grav versions prior to 1.7.42, update to version 1.7.42 or later to resolve the issue. As a temporary workaround, consider restricting access to the administrator screen and the edit functionality for users with page editing privileges until the update can be applied.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav
Twig